CVE-2018-4849
Last modified
CVE-2018-4849 is a vulnerability of currently unknown severity. A vulnerability has been identified in Siveillance VMS Video for Android (All versions < V12.1a (2018 R1)), Siveillance VMS Video for iOS (All versions < V12.1a (2018 R1)). Improper certificate validation could allow an attacker in a privileged network position to read data from and write data to the encrypted communication channel between the app and a server. EPSS estimates a 0.76% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in Siveillance VMS Video for Android (All versions < V12.1a (2018 R1)), Siveillance VMS Video for iOS (All versions < V12.1a (2018 R1)). Improper certificate validation could allow an attacker in a privileged network position to read data from and write data to the encrypted communication channel between the app and a server. The security vulnerability could be exploited by an attacker in a privileged network position which allows intercepting the communication channel between the affected app and a server (such as Man-in-the-Middle). Furthermore, an attacker must be able to generate a certificate that results for the validation algorithm in a checksum identical to a trusted certificate. Successful exploitation requires no user interaction. The vulnerability could allow reading data from and writing data to the encrypted communication channel between the app and a server, impacting the communication's confidentiality and integrity. At the time of advisory publication no public exploitation of this security vulnerability was known. Siemens confirms the security vulnerability and provides mitigations to resolve the security issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Siveillance Vms Video | < 12.1a |
References
- http://www.securityfocus.com/bid/104105Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/104105Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-4849?
How severe is CVE-2018-4849?
How do I fix CVE-2018-4849?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-4843A vulnerability has been identified in SIMATIC S7-400 CPU 4…6.5
- CVE-2018-4844A vulnerability has been identified in SIMATIC WinCC OA UI f…6.7
- CVE-2018-4845A vulnerability has been identified in RAPIDLab 1200 systems…8.8
- CVE-2018-4846A vulnerability has been identified in RAPIDLab 1200 systems…
- CVE-2018-4847A vulnerability has been identified in SIMATIC WinCC OA Oper…
- CVE-2018-4848A vulnerability has been identified in SCALANCE X-200 switch…
- CVE-2018-4850A vulnerability has been identified in SIMATIC S7-400 (incl.…
- CVE-2018-4851A vulnerability has been identified in SICLOCK TC100 (All ve…
- CVE-2018-4852A vulnerability has been identified in SICLOCK TC100 (All ve…
- CVE-2018-4853A vulnerability has been identified in SICLOCK TC100 (All ve…
- CVE-2018-4854A vulnerability has been identified in SICLOCK TC100 (All ve…
- CVE-2018-4855A vulnerability has been identified in SICLOCK TC100 (All ve…
Are you affected by CVE-2018-4849?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
